SOC2C

Is this your company? Buyers are checking Deepnote here. Claim deepnote.com free to control the listing, earn the badge buyers trust, and see who's evaluating you.

Claim free
Deepnote logo

Deepnote

Trust level
Listed
Unverified

Sourced from public information. Not yet verified by the company.

Deepnote is SOC 2 Type II compliant. Deepnote also holds GDPR, CCPA, and HIPAA.

Framework
Auditor
Last report
Renewal
View official trust center ↗

About

Deepnote is a widely-used collaborative data notebook trusted by top data teams in banks, healthcare, and Fortune 500 companies. We prioritized security and have built Deepnote to meet the highest security requirements. We help data teams stay secure and compliant by providing them with all the tools they need to enforce the security best practices. Any questions? We'd love to tell you more.

Compliance & infrastructure

Hosting
AWSGCPAzure

Documents

1

Subprocessors

19
  • A
    Amazon Web Services · Cloud infrastructure
    United States
  • A
    Anthropic · AI services
    United States
  • O
    Open AI · AI services
    United States
  • G
    Google Cloud Platform · Cloud infrastructure
    United States
  • G
    Google Workspace · Productivity & communication tools
    United States
  • C
    ChartMogul · Revenue analytics
    EU
  • H
    HubSpot · CRM & marketing automation
    United States
  • I
    Intercom · Customer support
    United States
  • P
    ProductBoard · Product management
    United States
  • S
    Stitch · Data pipelines (ETL)
    United States
  • S
    Stripe · Payment processing
    United States
  • W
    WorkOS · Authentication (SSO, SCIM)
    United States
Show all 19 subprocessors
  • M
    Microsoft Azure · Cloud infrastructure & AI
    United States
  • M
    Mailgun · Transactional email
    United States
  • S
    Sentry · Error monitoring
    United States
  • S
    Sprig · Product feedback
    United States
  • H
    Hetzner Cloud · Cloud infrastructure
    EU
  • M
    Mistral AI · AI Service
    EU
  • P
    PostHog · Product analytics
    United States

Compliance leadership

The person who leads Deepnote's SOC 2 isn't listed yet. Claim this profile to add it.

Penetration test

Unknown. Deepnote's penetration test vendor isn't listed yet.

Claim this profile to add it.

Recent updates

Welcome to Deepnote's Trust CenterAug 2025

When we have an update to our security policies or data subprocessors, you'll be notified here.

This listing is partial

7/11 details · 64%

SOC2C shows the verified essentials. 4 details are not yet provided by the company. Trust centers list more, so we invite the owner to fill the gaps here.

  • Auditorraises trust
    Add the CPA firm that issued your SOC 2 so buyers can verify who signed it.
  • Report dateraises trust
    Add your most recent report period so buyers see how current your SOC 2 is.
  • Renewal date
    Add your renewal window so buyers know your coverage is active.
  • Security controls
    Confirm key controls (encryption, MFA/SSO, annual pen test, BCP/DR) buyers screen for.
Claim free to control your listing

Verify your work email to take ownership, earn the badge buyers trust, and add the details that win deals.

Frequently asked

Is Deepnote SOC 2 compliant?
Deepnote is SOC 2 Type II compliant. On SOC2C this listing is Listed.
Is Deepnote GDPR compliant?
According to Deepnote's public trust center, Deepnote is GDPR compliant. On SOC2C this listing is Listed.
Is Deepnote CCPA compliant?
According to Deepnote's public trust center, Deepnote is CCPA compliant. On SOC2C this listing is Listed.
Is Deepnote HIPAA compliant?
According to Deepnote's public trust center, Deepnote is HIPAA compliant. On SOC2C this listing is Listed.
Is Deepnote SOC 2 Type I or Type II?
Deepnote is SOC 2 Type II compliant. A Type II report covers how security controls operated over a period (typically 3 to 12 months), a stronger signal than a point-in-time Type I.

Answers published by Deepnote

Reproduced from Deepnote's own trust center. These are the company's statements about its security practices — SOC2C has not tested or verified them, and they may have changed since we last read the page. Check the source ↗

Application security
#### Protecting your account We made a decision to not support password login and only use trusted third party login providers, Google and Github. Both support several means of multi-factor authentication (MFA) and have a solid level of security against brute force, or credentials stuffing attacks.   #### Access control for projects Projects have granular role-based access control (RBAC) settings, to allow you to choose what your collaborators can and cannot do. For more details, see the relevant documentation.   #### Defense in depth As we understand that no system will ever be 100% secure, we try to apply defense in depth in design of our apps. One specific example is how we approached identifiers: while we perform authorization checks on all endpoints, Ds for users or projects are high entropy UUIDs. This assures that even if an IDOR would occur in one of our applications, any large-scale exploitation would be much more difficult than with sequential identifiers.   #### Protecting your privacy You control and own your data and, whether it’s your personal or work information, we’re committed to keeping it private. Our privacy policy describes when we collect your information and why.   #### Protecting your source code, data and secrets All files in Deepnote are encrypted at rest, whether they are files you create there or anything you upload. The keys are managed and rotated automatically by our Cloud Service Provider. For sensitive information (such as database integrations or environment variables), we apply a layer of AES-256-CBC encryption before storing them in our database. Decryption keys are stored separately. All data transmitted between Deepnote and our users is protected using Transport Layer Security (TLS), and our Strict-Transport-Security (HSTS) settings assure that your browser will never send an unencrypted request to us.   #### Rigorous security testing We perform security testing on a regular basis to identify and patch…
Operational security
#### Team equipment All Deepnote team members' computers have up-to-date OS, have a strong passphrases and encrypted storage.   #### Team access We follow the principle of least privilege in how we write design our cloud infrastructure and how we access it. We use Google account authentication with two-factor authentication enforced for all accesses to production systems (many of us utilize FIDO2 tokens).   #### Code reviews Changes to source code destined for production systems are subject to code reviews by qualified engineering peers. We adhere to a secure development lifecycle and review the security implications of every change. Prior to updating production services, the contributors to the updated software version are required to verify that their changes are working as intended in the staging environment.